Skip to content
AI Act Recital 115 EN
LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this law. Contains: the full text of every article, recital and provision of this law. Everything links back to its source on overview.legal — legal information, not advice.

Recital 115 — systemic risk management for general-purpose AI

In force — consolidated2026-07-27 · CELEX 02024R1689-20260727 · ELI ↗
Version history 2
  • 2026-07-27in force CELEX 02024R1689-20260727
  • 2024-07-12 CELEX 02024R1689-20240712

Providers of general-purpose AI models with systemic risks should assess and mitigate possible systemic risks. If, despite efforts to identify and prevent risks related to a general-purpose AI model that may present systemic risks, the development or use of the model causes a serious incident, the general-purpose AI model provider should without undue delay keep track of the incident and report any relevant information and possible corrective measures to the Commission and national competent authorities. Furthermore, providers should ensure an adequate level of cybersecurity protection for the model and its physical infrastructure, if appropriate, along the entire model lifecycle. Cybersecurity protection related to systemic risks associated with malicious use or attacks should duly consider accidental model leakage, unauthorised releases, circumvention of safety measures, and defence against cyberattacks, unauthorised access or model theft. That protection could be facilitated by securing model weights, algorithms, servers, and data sets, such as through operational security measures for information security, specific cybersecurity policies, adequate technical and established solutions, and cyber and physical access controls, appropriate to the relevant circumstances and the risks involved.

Related across sources

Statement 3/2024 data protection authorities’ role in the Artificial Intelligence Act framework Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted… Statement ·EDPB Jul 16, 2024 Artificial Intelligence Single Point of Contact for AI Regulation Authority Cooperation
€24,000 Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) found that the Friuli Centrale University Health Authority (ASUFC) violated Articles 5(1)(f), 9, 25, and 32 of the GDPR based on a… Italy ·Garante ·Art. 5, 9, 25 +1 Sep 3, 2026 Integrity and Confidentiality Principle Data Breaches Right of Access
2025 EDPB Annual Report 2024 De EDPB heeft het Jaarraport van 2024 gepubliceerd. Met ook een handzame samenvatting voor degene die geen tijd hebben. Er wordt ook een lijst met zaken van enkele DPAs… Apr 23, 2025 Direct Marketing Legitimate Interest Privacy by Design
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer
Opinion 01/2025 EDPB- EDPS Joint Opinion 01/2025 on the Proposal for a Regulation on simplification measures for SMEs and SMCs, in particular the record-keeping obligation under Art. 30(5) GDPR De EDPB en EDPS steunen het doel om de administratieve lasten voor SMCs en MKB te verminderen, mits dit de bescherming van fundamentele rechten niet verlaagt. Ze benadrukken de… Opinion Jul 9, 2025 Accountability Criminal Data Processing